Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the TISAX cluster.
Primary documents
- VDA-ISA workbook โ the catalogue. Excel-format spreadsheet with controls, maturity-level criteria, scoring guidance. Current major version: 6.0 (late 2023), with maintenance updates through 2024-2025. Distributed by VDA via vda.de and via ENX participant portal.
- TISAX Participant Handbook โ ENX-published operational document describing the assessment process, label types, registration steps, audit-provider engagement. Updated periodically; current ~2024-2025.
- TISAX Assessment Provider Handbook โ operational guidance for audit providers. Less commonly read by suppliers but useful for understanding auditor expectations.
- VDA-ISA criteria mapping โ VDA-published spreadsheet mapping VDA-ISA controls to ISO/IEC 27001:2022 Annex A and other reference frameworks. Useful for dual-implementation orgs.
Operating bodies
- ENX Association โ neutral operator. Frankfurt-based. enx.com. Maintains the registry, accredits audit providers, runs the portal. Annual participant fees fund operations.
- VDA (Verband der Automobilindustrie) โ content owner. Authors and revises VDA-ISA. vda.de.
Accredited audit providers
ENX-accredited audit providers as of 2026 (illustrative, not exhaustive; check enx.com for current list):
- TรV SรD (Munich)
- TรV Rheinland (Cologne)
- TรV Nord (Hannover)
- TรV Hessen
- DEKRA (Stuttgart)
- DQS (Frankfurt)
- KPMG
- Deloitte
- PwC
- EY
- BSI Group (UK origin, German operations)
- GRC partner firms (specialist auditors with TISAX accreditation in addition to ISO 27001)
Auditor accreditation is checkable via the ENX portal participant view.
Required and recommended companion standards
- ISO/IEC 27001:2022 โ the international ISMS standard. Most controls overlap; implementations typically converge.
- ISO/IEC 27002:2022 โ controls implementation guidance.
- ISO/IEC 27005:2022 โ risk management. Useful for risk-assessment methodology underlying VDA-ISA control selection.
- ISO/IEC 27701:2019 โ privacy information management. Complements VDA-ISA Data Protection module.
- ISO/IEC 27017:2015 โ cloud-specific controls. Useful when supplier uses cloud-hosted services for automotive customer data.
- ISO/IEC 42001:2023 โ AI management system. No formal TISAX integration yet, but practitioners are using it as an AI-specific overlay.
- GDPR (EU 2016/679) โ privacy regulation. Data Protection module aligns explicitly.
Adjacent automotive-sector standards
- ISO/SAE 21434:2021 โ Road vehicles โ Cybersecurity engineering. Product-side cyber-security for vehicles. Different scope from TISAX (which is about supplier-org information security), but relevant for development partners working on connected / autonomous vehicle systems.
- UN R155 / UN R156 โ UN ECE regulations on vehicle cybersecurity (R155) and software update management (R156). Mandatory for vehicle type approval in UN member states from 2022.
- ASPICE (Automotive SPICE) โ software process maturity model for automotive. Same SPICE roots as TISAX maturity levels. Common in development-partner relationships alongside TISAX.
- VDA 6.x โ automotive quality management family (parallel to ISO 9001). Often required alongside TISAX in OEM contracts.
Named practitioners and reference voices
TISAX is a smaller practitioner community than ISO 27001. Named voices include:
- ENX Association staff โ public-facing communications, conference presentations, webinars. The most authoritative source on operational mechanics.
- VDA Information Security Working Group โ authors the catalogue. Less individually-attributed than ENX side.
- TรV / DEKRA / KPMG senior auditors โ industry-conference presentations, particularly at VDA events and Hannover Messe. Surface common findings and emerging audit focus areas.
- Mid-market German GRC consultancies (KPMG GRC, Deloitte Risk Advisory, PwC, EY, plus specialist Mittelstand-focused firms) โ practitioner content via industry publications.
For independent or critical voices, the field is thinner than for ISO 27001. Most TISAX writing is implementation-focused; critical analysis is rare in published form.
Reference resources
- enx.com โ official TISAX operating site. Participant portal, audit-provider list, handbook downloads.
- vda.de โ VDA-ISA distribution. German-language primary.
- VDA Information Security Conference โ annual industry event covering TISAX and adjacent automotive InfoSec.
- Hannover Messe โ broader industrial event with VDA / ENX presence.
- TISAX participant member webinars โ periodic ENX-hosted Q&A sessions, open to participants.
Regulatory and procurement context
- OEM contract clauses โ VW Group, BMW Group, Mercedes-Benz, Audi, Porsche, Bosch, Continental, ZF, Schaeffler, Hella, Mahle have TISAX flow-down clauses in supplier contracts. Wording varies but mechanism is consistent.
- GDPR enforcement on automotive PII โ telematics, customer-relationship, employee, dealer-network data. Data Protection label increasingly required by OEMs handling EU resident data.
- EU NIS2 Directive โ automotive critical-infrastructure operators in scope under member-state transposition. Overlap with TISAX coverage; non-equivalent.
- EU AI Act โ high-risk classification for some automotive AI use cases (driver monitoring, ADAS) brings additional obligations. ISO 42001 + TISAX combined positioning emerging.